πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.2K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ–‹οΈ SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version πŸ–‹οΈ

Cybersecurity researchers have disclosed multiple security flaw in the onpremise version of SysAid IT support software that could be exploited to achieve preauthenticated remote code execution with elevated privileges. The vulnerabilities, tracked as CVE20252775, CVE20252776, and CVE20252777, have all been described as XML External Entity XXE injections, which occur when an attacker is.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Reevaluating SSEs: A Technical Gap Analysis of Last-Mile Protection πŸ–‹οΈ

Security Service Edge SSE platforms have become the goto architecture for securing hybrid work and SaaS access. They promise centralized enforcement, simplified connectivity, and consistent policy control across users and devices. But there's a problem they stop short of where the most sensitive user activity actually happensthe browser. This isnt a small omission. Its a structural.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day to Breach U.S. Organization πŸ–‹οΈ

Threat actors with links to the Play ransomware family exploited a recently patched security flaw in Microsoft Windows as a zeroday as part of an attack targeting an unnamed organization in the United States. The attack, per the Symantec Threat Hunter Team, part of Broadcom, leveraged CVE202529824, a privilege escalation flaw in the Common Log File System CLFS driver. It was patched by.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ Times πŸ–‹οΈ

Cybersecurity researchers have discovered a malicious package on the Python Package Index PyPI repository that masquerades as a seemingly harmless Discordrelated utility but incorporates a remote access trojan. The package in question is discordpydebug, which was uploaded to PyPI on March 21, 2022. It has been downloaded 11,574 times and continues to be available on the opensource registry.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ–‹οΈ NSO Group Fined $168M for Targeting 1,400 WhatsApp Users With Pegasus Spyware πŸ–‹οΈ

A federal jury on Tuesday decided that NSO Group must pay Metaowned WhatsApp WhatsApp approximately 168 million in monetary damages, more than four months after a federal judge ruled that the Israeli company violated U.S. laws by exploiting WhatsApp servers to deploy Pegasus spyware, targeting over 1,400 individuals globally. WhatsApp originally filed the lawsuit against NSO Group in 2019,.

πŸ“– Read more.

πŸ”— Via "The Hacker News"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
🚨 UK pioneering global move away from passwords 🚨

Government to roll out passkey technology across digital services as an alternative to SMSbased verification.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 UK critical systems at increased risk from 'digital divide' created by AI threats 🚨

New report warns that organisations unable to defend AIenabled threats are exposed to greater cyber risk.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸš€ Toll road scams are in overdrive: Here’s how to protect yourself πŸš€

Have you received a text message about an unpaid road toll? Make sure youre not the next victim of a smishing scam.

πŸ“– Read more.

πŸ”— Via "ESET - WeLiveSecurity"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Passkeys Set to Protect GOV.UK Accounts Against Cyber-Attacks πŸ“”

The UK government has announced that it will be replace its current SMS verification system with passkeys by the end of 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ€”1
πŸ“” NSO Group Hit with $168m Fine for WhatsApp Pegasus Spyware Abuse πŸ“”

The Israeli spyware maker must pay 444,719 in compensatory damages to Meta and 167.25m in punitive damages.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ‘1
πŸ“” UK Government Warns Retail Attacks Must Serve as a β€œWake-up Call” πŸ“”

UK government minister Pat McFadden said during CYBERUK that the incidents affecting MS, Coop and Harrods show that cybersecurity is a necessity.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” UK Cyber Insurance Claims Second Highest on Record πŸ“”

Marsh says ransomware drove cyber insurance claims to second highest on record in 2024.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Talent Shortages Bite as 80% of UK Firms Hit with AI Threats πŸ“”

Half of UK firms have over 10 cyber positions unfilled, according to Cisco.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 Why Businesses Switch Cybersecurity Providers (And Lessons They Learn) 🌊

Most teams dont plan to replace their MDR, SOCaaS, or MSSP provider. It usually happens after monthssometimes yearsof frustrations stacking up missed alerts, vague reports, poor communication, and the slow realization that their cybersecurity provider simply isnt improving. Weve worked with dozens of teams in this exact situation. Some had just experienced a security breach The post Why Businesses Switch Cybersecurity Providers And Lessons They Learn appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🌊 How to Secure Your Google Meeting Tool Against Unauthorized AI Bots 🌊

Integrating a meeting tool like a chatbot into Google Meet can significantly enhance productivity by automating tasks like transcriptions, scheduling, and notetaking. However, security concerns arise when granting AI tools access to sensitive discussions and data. Unauthorized access, data leaks, and AI misuse are potential risks that organizations must address. By carefully configuring your chatbots The post How to Secure Your Google Meeting Tool Against Unauthorized AI Bots appeared first on UnderDefense.

πŸ“– Read more.

πŸ”— Via "UnderDefense"

----------
πŸ‘οΈ Seen on @cibsecurity
🚨 Preparing for post-quantum threat will make "fixing the Millennium Bug look easy" 🚨

NCSC's CTO urges organisations to recognise decadelong, nationalscale technology change required to prepare for the postquantum threat.

πŸ“– Read more.

πŸ”— Via "UK NCSC"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” DDoS-for-Hire Network Dismantled in International Operation πŸ“”

A prolific DDoSforhire network has been dismantled by Polish authorities as part of a coordinated international crackdown.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” "Nationally Significant" Cyber-Attacks Have Doubled, UK’s NCSC Reports πŸ“”

NCSC CEO Richard Horne said the cyber agency has managed twice as many nationally significant cyber incidents in the period from September 2024 to May 2025.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ“” Inferno Drainer Returns, Stealing Millions from Crypto Wallets πŸ“”

Inferno Drainer returns, stealing millions from crypto wallets through phishing on Discord.

πŸ“– Read more.

πŸ”— Via "Infosecurity Magazine"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ "Bring Your Own Installer" Attack Targets SentinelOne EDR πŸ•΅οΈβ€β™‚οΈ

Researchers from Aon's Stroz Friedberg incident response firm discovered a new attack type, known as "Bring Your Own Installer," targeting misconfigured SentinelOne EDR installs.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity
πŸ•΅οΈβ€β™‚οΈ Play Ransomware Group Used Windows Zero-Day πŸ•΅οΈβ€β™‚οΈ

Previously, Microsoft reported that Storm2460 had also used the privilege escalation bug to deploy ransomware on organizations in several countries.

πŸ“– Read more.

πŸ”— Via "Dark Reading"

----------
πŸ‘οΈ Seen on @cibsecurity